# Microsoft links more than 30 domains to MacSync Stealer activity

_Monday, August 17, 2026 at 8:00 PM EDT · Security · Latest · Tier 2 — Notable_

![Microsoft links more than 30 domains to MacSync Stealer activity — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLR2UjD4FhPqPT7MZpKuuqDl82K13qHQ_ob2-S_fK62g7UtwW6jn6YafX4RcZcqFgZWFbXiuCTkLbeD9zC_ws4mOUL0xVJgJ315fMiFlqxDFnhyphenhyphenIe2K8IXv3Vn1ZfWJevZywKd01wSpTS0BT08VlGtSoksz8y0ihBug5XqbRN48jy_NoQx-4fRc52Khzg/s1700-e365/apple-macos.jpg)

Microsoft Defender Experts linked more than 30 domains to MacSync Stealer after correlating endpoint behavior and network requests across changing infrastructure. Microsoft said the macOS-focused malware was actively exfiltrating data, collecting Keychain material, browser credentials and cookies, SSH keys, AWS credentials, Kubernetes configurations and files before splitting and uploading archives through HTTP PUT requests. The observed execution began with a Terminal session consistent with ClickFix social engineering, followed by curl retrieval and native-utility decoding.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/microsoft-links-30-rotating-domains-to.html)

---
Canonical: https://techandbusiness.org/newswire/SGFJb2j9dqxIeuxRdFwgoy
Retrieved: 2026-08-19T11:57:26.604Z
Publisher: Tech & Business (techandbusiness.org)
